cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 104 of 162
CVE-2018-18495P4MEDIUMCVSS 6.5fixed in 64.0≥ unspecified, < 642019-02-28
CVE-2018-18495 [MEDIUM] CWE-732 CVE-2018-18495: WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.
nvdosv
CVE-2021-43541P4MEDIUMCVSS 6.5fixed in 95.0≥ unspecified, < 952021-12-08
CVE-2021-43541 [MEDIUM] CVE-2021-43541: When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces w When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2020-26976P4MEDIUMCVSS 6.5fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26976 [MEDIUM] CVE-2020-26976: When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the fo When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.
nvd
CVE-2020-15655P4MEDIUMCVSS 6.5fixed in 79.0≥ unspecified, < 792020-08-10
CVE-2020-15655 [MEDIUM] CVE-2020-15655: A redirected HTTP request which is observed or modified through a web extension could bypass existin A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvdosv
CVE-2022-22736P4HIGHCVSS 7.0fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22736 [HIGH] CWE-427 CVE-2022-22736: If Firefox was installed to a world-writable directory, a local privilege escalation could occur whe If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for system libraries. However the install directory is not world-writable by default.*This bug only affects Firefox for Windows in a non-default installation. Other operating systems are unaffected.*. This vulner
nvd
CVE-2015-7575P4MEDIUMCVSS 5.9v38.0v38.0.1+10 more2016-01-09
CVE-2015-7575 [MEDIUM] CWE-19 CVE-2015-7575: Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
nvd
CVE-2020-15664P4MEDIUMCVSS 6.5fixed in 80.0≥ 78.0, < 78.2+1 more2020-10-01
CVE-2020-15664 [MEDIUM] CWE-863 CVE-2020-15664: By holding a reference to the eval() function from an about:blank window, a malicious webpage could By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firef
nvdosv
CVE-2020-26966P4MEDIUMCVSS 6.5fixed in 83.0fixed in 832020-12-09
CVE-2020-26966 [MEDIUM] CVE-2020-26966: Searching for a single word from the address bar caused an mDNS request to be sent on the local netw Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thu
nvd
CVE-2022-40959P4MEDIUMCVSS 6.5fixed in 105.0≥ unspecified, < 1052022-12-22
CVE-2022-40959 [MEDIUM] CWE-922 CVE-2022-40959: During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading t During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvd
CVE-2020-12415P4MEDIUMCVSS 6.5fixed in 78.0≥ unspecified, < 782020-07-09
CVE-2020-12415 [MEDIUM] CWE-276 CVE-2020-12415: When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and a When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78.
nvdosv
CVE-2020-15653P4MEDIUMCVSS 6.5fixed in 79.0≥ unspecified, < 792020-08-10
CVE-2020-15653 [MEDIUM] CVE-2020-15653: An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. Th An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvdosv
CVE-2021-23975P4MEDIUMCVSS 6.5fixed in 86.0fixed in 862021-02-26
CVE-2021-23975 [MEDIUM] CWE-862 CVE-2021-23975: The developer page about:memory has a Measure function for exploring what object types the browser h The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function was invoked we incorrectly called the sizeof function, instead of using the API method that checks for invalid pointers. This vulnerability affects Firefox < 86.
nvdosv
CVE-2021-23956P4MEDIUMCVSS 6.5fixed in 85.0fixed in 852021-02-26
CVE-2021-23956 [MEDIUM] CVE-2021-23956: An ambiguous file picker design could have confused users who intended to select and upload a single An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading a whole directory. This was addressed by adding a new prompt. This vulnerability affects Firefox < 85.
nvdosv
CVE-2023-6860P4MEDIUMCVSS 6.5fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6860 [MEDIUM] CVE-2023-6860: The `VideoBridge` allowed any content process to use textures produced by remote decoders. This cou The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2006-2788P4HIGHCVSS 7.5v0.8v0.9+18 more2006-06-02
CVE-2006-2788 [HIGH] CWE-119 CVE-2006-2788: Double free vulnerability in the getRawDER function for nsIX509Cert in Firefox allows remote attacke Double free vulnerability in the getRawDER function for nsIX509Cert in Firefox allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via certain Javascript code.
nvd
CVE-2020-26975P4MEDIUMCVSS 6.5fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26975 [MEDIUM] CVE-2020-26975: When a malicious application installed on the user's device broadcast an Intent to Firefox for Andro When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed headers. *Note: This issue only affected Firefox for Android. Other operating sys
nvd
CVE-2023-6204P4MEDIUMCVSS 6.5fixed in 120.0≥ unspecified, < 1202023-11-21
CVE-2023-6204 [MEDIUM] CWE-125 CVE-2023-6204: On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bo On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2021-38507P4MEDIUMCVSS 6.5fixed in 94.0≥ unspecified, < 942021-12-08
CVE-2021-38507 [MEDIUM] CWE-346 CVE-2021-38507: The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upg The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port 80. However, if a second encrypted port on the same IP address (e.g. port 8443) did not opt-in to opportunistic
nvd
CVE-2022-28285P4MEDIUMCVSS 6.5fixed in 99.0≥ unspecified, < 992022-12-22
CVE-2022-28285 [MEDIUM] CWE-125 CVE-2022-28285: When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet When generating the assembly code for MLoadTypedArrayElementHole, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
nvd
CVE-2022-34479P4MEDIUMCVSS 6.5fixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-34479 [MEDIUM] CWE-451 CVE-2022-34479: A malicious website that could create a popup could have resized the popup to overlay the address ba A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. *This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102
nvd
Mozilla Firefox vulnerabilities | cvebase